SOC Lead

Gizli Şirket

Ataşehir

On-site

TRY 360,000 - 500,000

Full time

8 days ago
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

Gizli Şirket seeks an experienced cybersecurity professional to monitor and respond to incidents across IT and OT environments. You will lead end-to-end IR actions, perform forensics, and apply MITRE ATT&CK to strengthen defenses while coordinating with cross-functional teams.

The role requires deep knowledge of Windows/Linux, network security, and hands-on scripting to automate responses. English proficiency is essential for international collaboration.

Qualifications

  • Bachelor's degree in Computer Engineering, Electrical-Electronics Engineering or related field.
  • Minimum 7 years of experience in Cyber Security Operations (SOC), Incident Response (IR), or Threat Hunting.
  • Deep knowledge of Windows and Linux operating system architectures, with proven experience in Digital Forensics.
  • Strong understanding of network security, TCP/IP protocols, network architectures, and traffic analysis.
  • Proficiency in managing and analyzing data from core security solutions: EDR, SIEM, SOAR, Firewall, IPS/IDS, Sandbox, Packet Capture, and NDR.
  • Hands-on scripting experience in Python, PowerShell, or Bash to build automation and response tools for security operations.
  • Excellent command of English (both written and verbal) to collaborate with international teams.

Responsibilities

  • Monitor, prioritize, and analyze cyber security incidents across IT and OT environments.
  • Lead end-to-end incident response actions against critical cyber threats.
  • Perform digital forensics investigations on Windows/Linux and network devices; conduct RCA and remediation actions.
  • Use MITRE ATT&CK to analyze adversary TTPs for proactive defense.
  • Conduct proactive threat hunting using system and network logs.
  • Design, update, and optimize correlation/detection rules and use cases on SIEM/EDR.
  • Create and maintain Incident Response Playbooks and coordinate with cross-functional teams for Tabletop Exercises.
  • Prepare technical analysis reports, incident assessments, and threat briefs for technical teams and senior management.
  • Identify security gaps and track remediation with infrastructure and application teams.

Skills

Cyber security operations
Incident response
Threat hunting
Digital forensics
Scripting (Python/PowerShell/Bash)
English communications
MITRE ATT&CK

Education

Bachelor in Computer Engineering or related

Tools

EDR
SIEM
SOAR
Firewall
IPS/IDS
Sandbox
Packet Capture
NDR

Job description

Job Description
  • Monitor, prioritize, and analyze cyber security incidents across both IT and OT environments from end to end.
  • Lead end-to-end incident response actions against critical cyber threats, including malware infections, ransomware attacks, unauthorized access attempts, and data leaks, ensuring containment and mitigation.
  • Perform digital forensics investigations on Windows/Linux operating systems and network devices; conduct Root Cause Analysis (RCA) and implement corrective/preventive actions.
  • Utilize the MITRE ATT&CK Framework to analyze adversary tactics, techniques, and procedures (TTPs) to enhance proactive defense mechanisms.
  • Conduct proactiveThreat Huntingactivities utilizing system and network logs to identify hidden threats and anomalous behaviors.
  • Design, update, and optimize correlation rules, detection rules, and use cases on SIEM and EDR platforms to improve visibility and detection capabilities.
  • Create and maintain Incident Response Playbooks, and coordinate with cross-functional teams to conduct Tabletop Exercises.
  • Prepare comprehensive technical analysis reports, incident assessments, and threat briefs for both technical teams and senior management.
  • Identify security gaps, develop remediation recommendations, and track their implementation in coordination with relevant infrastructure and application teams.
Qualifications
  • Bachelor’s degree in Computer Engineering, Electrical-Electronics Engineering or related fields,
  • Minimum 7 years of experience in Cyber Security Operations (SOC), Incident Response (IR), or Threat Hunting,
  • Deep knowledge of Windows and Linux operating system architectures, with proven experience in Digital Forensics,
  • Strong understanding of network security, TCP/IP protocols, network architectures, and traffic analysis,
  • Proficiency in managing and analyzing data from core security solutions: EDR, SIEM, SOAR, Firewall, IPS/IDS, Sandbox, Packet Capture, and NDR,
  • Hands-on scripting experience in Python, PowerShell, or Bash to build automation and response tools for security operations,
  • Excellent command of English (both written and verbal) to collaborate with international teams and analyze global threat intelligence.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Cyber Security Engineer
Cyber Security Engineer

GİZLİ • Fatih

On-site
TRY 350,000 - 520,000
Information Security Specialist
Information Security Specialist

Aygaz • Fatih

On-site
TRY 450,000 - 650,000
Senior AI Security Operations Engineer
Senior AI Security Operations Engineer

Treomind • Fatih

On-site
TRY 930,000 - 1,396,000
Senior Cyber Incident Responder – Hybrid SOC Leader
Senior Cyber Incident Responder – Hybrid SOC Leader

Softtech • Fatih

Hybrid
TRY 300,000 - 420,000
Private medical insurance
Group life insurance
Meal allowances
+5
Senior Infrastructure and Application Security Specialist
Senior Infrastructure and Application Security Specialist

Gizli • Fatih

On-site
TRY 300,000 - 500,000
Senior Cyber Incident Responder - Lead IR & SOC Excellence
Senior Cyber Incident Responder - Lead IR & SOC Excellence

Softtech • Turkey

Hybrid
TRY 420,000 - 640,000
Private medicalinsurance and groupife
Meal allowance
Travel and accommodation support
+2
Senior SOC Incident Response Lead & Threat Hunter
Senior SOC Incident Response Lead & Threat Hunter

Gizli Şirket • Ataşehir

On-site
TRY 360,000 - 500,000
Information Security Manager
Information Security Manager

Aygaz A.Ş. • Ümraniye

On-site
TRY 600,000 - 1,000,000
Information Security Manager
Information Security Manager

Aygaz • Ümraniye

On-site
TRY 450,000 - 750,000
Cyber Prevent Manager
Cyber Prevent Manager

Vodafone Group Plc • Fatih

On-site
TRY 3,263,000 - 5,595,000